cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
12567
Views
5
Helpful
7
Replies

Cisco ISE MAB Authentication Problem

ecejhe-old
Level 1
Level 1

I am facing problem with my MAB Policy.

Device ISE 2.2

Switch 2960

 

Problem:Not able to authenticate IP phone using MAB

Below the MAB debug:

May 31 13:03:06.261: %ILPOWER-5-IEEE_DISCONNECT: Interface Gi1/0/13: PD removed
May 31 13:03:06.800: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/0/13, changed state to down
May 31 13:03:07.534: %ILPOWER-7-DETECT: Interface Gi1/0/13: Power Device detected: IEEE PD
May 31 13:03:07.799: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/13, changed state to down
May 31 13:03:08.698: %ILPOWER-5-POWER_GRANTED: Interface Gi1/0/13: Power granted
May 31 13:03:12.078: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/13, changed state to up
May 31 13:03:13.081: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/0/13, changed state to up
May 31 13:03:16.233: %DOT1X-5-FAIL: Authentication failed for client (Unknown MAC) on Interface Gi1/0/13 AuditSessionID 0A0A761E00000058006B213E
May 31 13:03:16.233: %AUTHMGR-7-RESULT: Authentication result 'no-response' from 'dot1x' for client (Unknown MAC) on Interface Gi1/0/13 AuditSessionID 0A0A761E00000058006B213E
May 31 13:03:16.233: %AUTHMGR-7-FAILOVER: Failing over from 'dot1x' for client (Unknown MAC) on Interface Gi1/0/13 AuditSessionID 0A0A761E00000058006B213E
May 31 13:03:16.233: mab-ev(Gi1/0/13): Received MAB context create from AuthMgr
May 31 13:03:16.233: mab-ev(Gi1/0/13): Created MAB client context 0xA5000032
May 31 13:03:16.233: mab : initial state mab_initialize has enter
May 31 13:03:16.237: mab-sm(Gi1/0/13): Received event 'MAB_START' on handle 0xA5000032
May 31 13:03:16.237: mab : during state mab_initialize, got event 4(mabStart)
May 31 13:03:16.237: @@@ mab : mab_initialize -> mab_acquiring
May 31 13:03:24.993: mab-ev: Received NEW MAC (64a0.e7f6.7e44) for 0xA5000032
May 31 13:03:24.993: %AUTHMGR-5-START: Starting 'mab' for client (64a0.e7f6.7e44) on Interface Gi1/0/13 AuditSessionID 0A0A761E00000058006B213E
May 31 13:03:24.996: mab-sm(Gi1/0/13): Received event 'MAB_AVAILABLE' on handle 0xA5000032
May 31 13:03:24.996: mab : during state mab_acquiring, got event 7(mabAvailable)
May 31 13:03:24.996: @@@ mab : mab_acquiring -> mab_authorizing
May 31 13:03:24.996: mab-ev(Gi1/0/13): Sending create new context event to EAP from MAB for 0xA5000032 (64a0.e7f6.7e44)
May 31 13:03:24.996: mab-ev: formatted mac = 64a0e7f67e44
May 31 13:03:24.996: mab-ev: created mab pseudo dot1x profile dot1x_mac_auth_64a0.e7f6.7e44
May 31 13:03:24.996: mab-ev(Gi1/0/13): Starting MAC-AUTH-BYPASS for 0xA5000032 (64a0.e7f6.7e44)
May 31 13:03:24.996: mab-ev: Invalid EVT 9 from EAP
May 31 13:03:24.996: mab-ev: Invalid EVT 9 from EAP
May 31 13:03:25.000: mab-ev(Gi1/0/13): MAB received an Access-Reject for 0xA5000032 (64a0.e7f6.7e44)
May 31 13:03:25.003: %MAB-5-FAIL: Authentication failed for client (64a0.e7f6.7e44) on Interface Gi1/0/13 AuditSessionID 0A0A761E00000058006B213E
May 31 13:03:25.003: mab-sm(Gi1/0/13): Received event 'MAB_RESULT' on handle 0xA5000032
May 31 13:03:25.003: mab : during state mab_authorizing, got event 5(mabResult)
May 31 13:03:25.003: @@@ mab : mab_authorizing -> mab_terminate
May 31 13:03:25.003: mab-ev(Gi1/0/13): Deleted credentials profile for 0xA5000032 (dot1x_mac_auth_64a0.e7f6.7e44)
May 31 13:03:25.003: mab-ev(Gi1/0/13): Sending event (2) to AuthMGR for 64a0.e7f6.7e44
May 31 13:03:25.003: %AUTHMGR-7-RESULT: Authentication result 'no-response' from 'mab' for client (64a0.e7f6.7e44) on Interface Gi1/0/13 AuditSessionID 0A0A761E00000058006B213E
May 31 13:03:25.003: %AUTHMGR-7-FAILOVER: Failing over from 'mab' for client (64a0.e7f6.7e44) on Interface Gi1/0/13 AuditSessionID 0A0A761E00000058006B213E
May 31 13:03:25.003: %AUTHMGR-7-NOMOREMETHODS: Exhausted all authentication methods for client (64a0.e7f6.7e44) on Interface Gi1/0/13 AuditSessionID 0A0A761E00000058006B213E
May 31 13:03:25.003: %AUTHMGR-5-FAIL: Authorization failed or unapplied for client (64a0.e7f6.7e44) on Interface Gi1/0/13 AuditSessionID 0A0A761E00000058006B213E
May 31 13:03:25.003: mab-sm(Gi1/0/13): Received event 'MAB_DELETE' on handle 0xA5000032
May 31 13:03:25.003: mab-ev(Gi1/0/13): Received ABORT event from Auth Mgr for 0xA5000032 (64a0.e7f6.7e44)
May 31 13:03:25.003: mab-ev(Gi1/0/13): Deleted credentials profile for 0xA5000032 (dot1x_mac_auth_64a0.e7f6.7e44)
May 31 13:03:25.003: mab-ev: Freed MAB client context

 

TEST-SW#sh authentication sessions interface gi1/0/1
Interface: GigabitEthernet1/0/13
MAC Address: 64a0.e7f6.7e44
IP Address: 10.10.114.118
User-Name: 64a0e7f67e44
Status: Authz Failed
Domain: DATA
Oper host mode: multi-auth
Oper control dir: both
Session timeout: N/A
Idle timeout: N/A
Common Session ID: 0A0A761E00000058006B213E
Acct Session ID: 0x0000005E
Handle: 0x77000059

Runnable methods list:
Method State
dot1x Failed over
mab Failed over

 

Switch Configuration:

aaa new-model

!
aaa authentication login console local
aaa authentication login vty local
aaa authentication enable default enable
aaa authentication dot1x default group ST-RADIUS
aaa authorization exec default local
aaa authorization exec vty local
aaa authorization network default group ST-RADIUS
aaa authorization auth-proxy default group ST-RADIUS
aaa accounting update periodic 5
aaa accounting auth-proxy default start-stop group ST-RADIUS
aaa accounting dot1x default start-stop group ST-RADIUS

!

ip domain-name <domain-name>
ip name-server <ip>
ip device tracking

!

dot1x system-auth-control
spanning-tree mode pvst
spanning-tree extend system-id

!

interface FastEthernet0
no ip address
shutdown
!
interface GigabitEthernet1/0/1
switchport access vlan 117
switchport mode access
switchport voice vlan 114
authentication event fail action next-method
authentication host-mode multi-auth
authentication open
authentication order dot1x mab
authentication priority dot1x mab
authentication port-control auto
mab
snmp trap mac-notification change added
snmp trap mac-notification change removed
spanning-tree portfast
!
interface GigabitEthernet1/0/2
switchport access vlan 117
switchport mode access
switchport voice vlan 114
authentication event fail action next-method
authentication host-mode multi-auth
authentication open
authentication order dot1x mab
authentication priority dot1x mab
authentication port-control auto
mab 
snmp trap mac-notification change added
snmp trap mac-notification change removed
spanning-tree portfast
!

 ommited

!

logging source-interface Vlan118
logging host <ip>  transport udp port 20514
!
snmp-server community public RO
snmp-server enable traps snmp linkdown linkup
snmp-server enable traps mac-notification change move threshold
snmp-server host <ip>  version 2c mac-notification
snmp-server host <ip> version 2c public mac-notification

!

radius-server attribute 6 on-for-login-auth
radius-server attribute 6 support-multiple
radius-server attribute 8 include-in-access-req
radius-server attribute 25 access-request include
radius-server dead-criteria tries 3
radius-server deadtime 30
radius-server vsa send accounting
radius-server vsa send authentication
!
radius server ST-ISE
address ipv4 10.10.118.230 auth-port 1812 acct-port 1813
key C1sc0234
!
line con 0
line vty 5 15
!
ntp server <ip>
end

=================

ISE has its default Policy for MAB and dot1x. Dot1x is working fine and able to authenticate domain computers but MAB for Cisco IP Phones 6921, 2907 having issues.

 

Is there any problem with my configurations?

 

thanks

 

 

 

1 Accepted Solution

Accepted Solutions

ecejhe-old
Level 1
Level 1

Please select option 1 and 5

 

ISE/iseadmin# application configure ise

 

Selection ISE configuration option

[1]Reset M&T Session Database

[2]Rebuild M&T Unusable Indexes

[3]Purge M&T Operational Data

[4]Reset M&T Database

[5]Refresh Database Statistics

[6]Display Profiler Statistics

[7]Export Internal CA Store

[8]Import Internal CA Store

[9]Create Missing Config Indexes

[10]Create Missing M&T Indexes

[11]Enable/Disable ACS Migration

[12]Generate Daily KPM Stats

[13]Generate KPM Stats for last 8 Weeks

[14]Enable/Disable Counter Attribute Collection

[15]View Admin Users

[16]Get all Endpoints

[17]Enable/Disable Wifi Setup

[18]Reset Config Wifi Setup

[19]Exit

 

Please note doing the above will restart the services.

 

All are now working

View solution in original post

7 Replies 7

ecejhe-old
Level 1
Level 1

IP phone was connected to gi1/0/13 same interface config of gi1/0/1

It seems that ISE is rejecting the MAB authentication for the IP phone.

What does your ISE Operations Log say?

Patrick

ISE log says its successfully authenticated. But switch seems still failed. Not sure why it is failing on the switch.. Any thoughts?

Now, just rebooted the ISE and both dot1x and MAB are now failing. Dot1x now cant profile my laptop and it falls to unknown device type. No other chamges on the ISE..

Attache the ISE Policy and live logs

Attached the ISE Policy and live logs

ecejhe-old
Level 1
Level 1

Please select option 1 and 5

 

ISE/iseadmin# application configure ise

 

Selection ISE configuration option

[1]Reset M&T Session Database

[2]Rebuild M&T Unusable Indexes

[3]Purge M&T Operational Data

[4]Reset M&T Database

[5]Refresh Database Statistics

[6]Display Profiler Statistics

[7]Export Internal CA Store

[8]Import Internal CA Store

[9]Create Missing Config Indexes

[10]Create Missing M&T Indexes

[11]Enable/Disable ACS Migration

[12]Generate Daily KPM Stats

[13]Generate KPM Stats for last 8 Weeks

[14]Enable/Disable Counter Attribute Collection

[15]View Admin Users

[16]Get all Endpoints

[17]Enable/Disable Wifi Setup

[18]Reset Config Wifi Setup

[19]Exit

 

Please note doing the above will restart the services.

 

All are now working

Review Cisco Networking products for a $25 gift card